Search CVE reports
61 – 63 of 63 results
Some fixes available 3 of 7
Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to read (1) hashes of former passwords and (2) ticket correspondence history by leveraging access to a privileged account.
4 affected packages
request-tracker4, request-tracker3.6, request-tracker3.8, rt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
request-tracker4 | — | — | — | — |
request-tracker3.6 | — | — | — | — |
request-tracker3.8 | — | — | — | — |
rt | — | — | — | — |
Some fixes available 3 of 7
Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4 affected packages
request-tracker3.6, request-tracker3.8, request-tracker4, rt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
request-tracker3.6 | — | — | — | — |
request-tracker3.8 | — | — | — | — |
request-tracker4 | — | — | — | — |
rt | — | — | — | — |
Some fixes available 3 of 7
The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for disabled user accounts, which makes it easier for context-dependent attackers to...
3 affected packages
request-tracker4, request-tracker3.6, request-tracker3.8
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
request-tracker4 | — | — | — | — |
request-tracker3.6 | — | — | — | — |
request-tracker3.8 | — | — | — | — |